Skip to content Skip to main navigation Skip to footer

Windows Will Not Reinstall the Windows UEFI CA 2023 Certificates

Problem

Windows does not reinstall the Windows UEFI CA 2023 Secure Boot certificates after the system’s Secure Boot certificate databases have been reverted to the older 2011 certificate set.

Cause

The system was previously updated to boot using the Windows UEFI CA 2023 certificates. However, the firmware Secure Boot certificate databases were later restored or reverted to the 2011 certificate set.

As a result, the system may still contain 2023-signed Windows boot files, but the firmware no longer trusts the Windows UEFI CA 2023 certificate required to boot those files with Secure Boot enabled.

Symptoms

When attempting to run the Secure Boot certificate update again:

  • AvailableUpdates is reset to 0.

  • UEFICA2023Status is briefly set to InProgress.

  • Shortly afterward, UEFICA2023Status returns to NotStarted.

  • The Windows UEFI CA 2023 certificates are not restored.

Solution

Temporarily restore Windows boot files signed by the 2011 certificate set, enable Secure Boot, and then run the Windows Secure Boot update process again.

At minimum, restore the 2011-signed versions of the following files:

\EFI\Boot\bootx64.efi
\EFI\Microsoft\Boot\bootmgfw.efi

One way to do this from Windows is to use TBOSDT.

Restoring the 2011-Signed Boot Files with TBOSDT

Start TBOSDT as an Administrator.

Change to aggressive locking:

set option locking 2

List the hard drives to find the drive containing the EFI System Partition:

list hd 0
list hd 1

Continue checking drives as needed. Locate the partition with a type similar to:

EFI System (FAT-32)

Note the partition ID shown in parentheses. This ID is needed to mount the EFI System Partition.

For example, if the EFI System Partition is on hard drive 0 and has partition ID 01, mount it with:

mount 0: 0 0x01

Make backup copies of the existing boot files in case they need to be restored later:

copy 0:\efi\boot\bootx64.efi 0:\efi\boot\bootx64_org.efi
copy 0:\efi\microsoft\boot\bootmgfw.efi 0:\efi\microsoft\boot\bootmgfw_org.efi

Copy the 2011-signed Windows boot file from Windows to the EFI System Partition:

copy /y c:\windows\boot\efi\bootmgfw.efi 0:\efi\boot\bootx64.efi
copy /y c:\windows\boot\efi\bootmgfw.efi 0:\efi\microsoft\boot\bootmgfw.efi

Unmount the EFI System Partition:

umount 0:

Reboot the system and enter the BIOS/UEFI setup:

reboot /b

Enable Secure Boot in the BIOS/UEFI setup.

After restoring the 2011-signed boot files and enabling Secure Boot, boot Windows.

Run the Windows Secure Boot Update

From an elevated Command Prompt, run:

reg add HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot /v AvailableUpdates /t REG_DWORD /d 0x5944 /f
schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"

Reboot the system.

After Windows starts again, run the Secure Boot update task a second time:

schtasks /Run /TN "\Microsoft\Windows\PI\Secure-Boot-Update"

Verification

When the update completes successfully, the following registry value should show:

UEFICA2023Status = Updated

Registry location:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecureBoot\Servicing

You may also verify that the Windows UEFI CA 2023 certificate has been restored to the firmware Secure Boot database by running the following command from an elevated PowerShell prompt:

Get-SecureBootUEFI -Name db -Decoded

Look for an entry for:

Windows UEFI CA 2023

Notes

Do not attempt to complete the Windows UEFI CA 2023 update while the system can only boot with Secure Boot disabled. The system must be able to boot successfully with Secure Boot enabled, using boot files trusted by the current firmware Secure Boot database, before Windows can reliably apply the Secure Boot certificate update.

After the Windows UEFI CA 2023 certificates are restored and the update status shows Updated, Windows can again install and use the 2023-signed Windows boot files.

Was This Article Helpful?

1